Impact
A vulnerability exists in Webkul Bagisto in the Admin Customer Impersonation Feature. By manipulating the ID argument in the /admin/customers/login-as-customer/ endpoint, an attacker can bypass authorization controls and assume the identity of any customer. This allows the attacker to access personal customer information, view orders, and perform actions on behalf of the customer. The flaw is classified as an improper authorization weakness (CWE-285). The vulnerability can be exploited remotely and has been publicly disclosed, indicating that attackers may already be attempting to use it.
Affected Systems
Webkul Bagisto version 2.4.x, including all releases up to and including 2.4.4, are affected. The issue resides in the admin customer impersonation feature. No later major releases are known to contain the bug at the time of this analysis.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate severity. EPSS information is not available and the CVE is not listed in the CISA KEV catalog, suggesting that while the flaw is exploitable, it may not be widely targeted yet. Attackers who can access the admin interface can gain unauthorized customer access, potentially leading to data exposure and fraudulent activity. The remote nature of the attack requires that the attacker has network access to the application or can trick an administrator into executing the vulnerable action.
OpenCVE Enrichment